Elastic

Elasticsearch

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 01.09.2026 19:20:10
  • Zuletzt bearbeitet 04.09.2026 20:04:06

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory ...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:14:03
  • Zuletzt bearbeitet 01.09.2026 14:28:15

Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bou...

  • EPSS 0.33%
  • Veröffentlicht 13.08.2026 19:13:45
  • Zuletzt bearbeitet 01.09.2026 14:15:50

The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the b...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:40
  • Zuletzt bearbeitet 01.09.2026 14:08:36

Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated user holding only read privileg...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:38
  • Zuletzt bearbeitet 01.09.2026 14:21:10

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single request containing a specially c...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:36
  • Zuletzt bearbeitet 01.09.2026 15:31:04

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one specially crafted search request...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:33
  • Zuletzt bearbeitet 01.09.2026 15:31:26

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit one small, specially crafted se...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:26
  • Zuletzt bearbeitet 04.09.2026 20:17:23

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:11:04
  • Zuletzt bearbeitet 01.09.2026 15:26:56

Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, te...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:11:02
  • Zuletzt bearbeitet 01.09.2026 15:28:17

Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to ...